Subject: IP Filer upgrade gone wrong
To: None <port-mac68k@NetBSD.org>
From: Herb Singleton <hsingleton@mac.com>
List: port-mac68k
Date: 02/24/2002 00:39:09
I am currently running a cable modem/NAT setup on NetBSD 1.5.1. I'm 
trying to update to IP Filter 3.4.23. I've followed the directions for 
compiling IPF as given in the NetBSD section of the IP Filter FAQ, and 
IPF and the NetBSD kernel seem to compile successfully.

However, after installing IPF and the new kernel, NAT no longer works. 
"ipf -V" gives me the correct IPF and kernel version. I can connect to 
the net from the NetBSD box, and I can talk back and forth between the 
NetBSD box and my internal network, but I can't get NAT to work at all. 
Replacing the kernel with the stock NetBSD 1.5.1 GENERIC kernel restores 
NAT, although "ipf -V" gives conflicting versions for ipf and the 
kernel, and ipf reports a bunch of errors when it's called.

I've tried serveral variations on ipf.conf (including a blank ipf.conf), 
and that doesn't seem to help.

My ipnat.conf is:

##
map sn0 192.168.3.0/24 -> 0.0.0.0/32 portmap tcp 10000:40000
map sn0 192.168.3.0/24 -> 0/32
##

Has anyone seen a problem like this? If not, how do I go about restoring 
IPF 3.4.9?

Thanks

<----------------------------------------------->
Herb Singleton
hsingleton@mac.com
http;//www.cross-spectrum.com